aa_af_perm
int aa_af_perm(const struct cred *subj_cred, struct aa_label *label,
error = aa_af_perm(current_cred(), label, OP_CREATE,